Description
Arcserve UDP prior to 9.2 contains a path traversal vulnerability in com.ca.arcflash.ui.server.servlet.FileHandlingServlet.doUpload(). An unauthenticated remote attacker can exploit it to upload arbitrary files to any location on the file system where the UDP agent is installed.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-46459 | Arcserve UDP prior to 9.2 contains a path traversal vulnerability in com.ca.arcflash.ui.server.servlet.FileHandlingServlet.doUpload(). An unauthenticated remote attacker can exploit it to upload arbitrary files to any location on the file system where the UDP agent is installed. |
References
| Link | Providers |
|---|---|
| https://www.tenable.com/security/research/tra-2023-37 |
|
History
No history.
Status: PUBLISHED
Assigner: tenable
Published:
Updated: 2024-08-02T19:16:49.527Z
Reserved: 2023-09-06T18:06:47.116Z
Link: CVE-2023-42000
No data.
Status : Modified
Published: 2023-11-27T17:15:08.160
Modified: 2024-11-21T08:22:05.270
Link: CVE-2023-42000
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD